CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1234 | CVE-1999-1254 | Candidate | Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables. | Proposed (20010912) | ACCEPT(3) Cole, Frech, Wall | MODIFY(1) Meunier | NOOP(2) Christey, Foat | Christey> Need to get feedback from MS on this. | Christey> (prompted from Pascal Meunier) should this be treated | as a general design issue with ICMP? Or is it a specific | implementation flaw that only affects Reliant? | Meunier> The description is too narrow and incorrect. Spoofed ICMP | redirect messages can be used to setup man-in-the-middle attacks | instead of a DoS. There"s no reason that this behavior would be | limited to Windows, as it is specified by the standard. As I said | elsewhere, ICMP messages should not be acted upon without access | controls. | View |
1490 | CVE-1999-1510 | Candidate | Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via long (1) USER, (2) LIST, or (3) CWD commands. | Proposed (20010912) | ACCEPT(3) Cole, Foat, Frech | NOOP(1) Wall | View | |
1235 | CVE-1999-1255 | Candidate | Hyperseek allows remote attackers to modify the hyperseek configuration by directly calling the admin.cgi program with an edit_file action parameter. | Proposed (20010912) | ACCEPT(2) Cole, Frech | NOOP(2) Foat, Wall | View | |
1491 | CVE-1999-1511 | Candidate | Buffer overflows in Xtramail 1.11 allow attackers to cause a denial of service (crash) and possibly execute arbitrary commands via (1) a long PASS command in the POP3 service, (2) a long HELO command in the SMTP service, or (3) a long user name in the Control Service. | Proposed (20010912) | ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | View | |
1236 | CVE-1999-1256 | Candidate | Oracle Database Assistant 1.0 in Oracle 8.0.3 Enterprise Edition stores the database master password in plaintext in the spoolmain.log file when a new database is created, which allows local users to obtain the password from that file. | Proposed (20010912) | ACCEPT(2) Cole, Frech | NOOP(2) Foat, Wall | View |
Page 255 of 20943, showing 5 records out of 104715 total, starting on record 1271, ending on 1275